Skip to main content
Question

How can we get cribl to keep the time within the log?

  • March 11, 2025
  • 37 replies
  • 140 views

Show first post

37 replies

  • Author
  • Employee
  • March 11, 2025

Brendan, I am having the linux engineer run that when thye get back, but I am almost 100% positive that it is in UTC. All servers/appliances are set to UTC


Forum|alt.badge.img
  • Participating Frequently
  • March 11, 2025

Same for Cribl? :wink:


  • Author
  • Employee
  • March 11, 2025

I think what I am going to do is just use index time. It is not ideal, but to keep up with all the 1000's of desktops is not sustainable.


David Maislin

The latest release of Cribl supports S2S v4 which would accept the OS time when the UF connects to Cribl.


David Maislin

Does that help at least for the Splunk side of things?


  • Author
  • Employee
  • March 11, 2025

hmmm, okay I will check this out


  • Author
  • Employee
  • March 11, 2025

I applied that change, and it looks like the events are still coming in mixed up. For example it is 13:33 my time but events are bing index -5 hours


David Maislin

`date`


David Maislin

What is the time showing where the forwarder is running?


  • Author
  • Employee
  • March 11, 2025

So this is what is really odd. Here is an _internal log and this is behaving as expected


David Maislin

And what is the version of the forwarder?


  • Author
  • Employee
  • March 11, 2025

ohh, I see in the internal log, it has -0500